Join our Newsletter — 33% off our NHI Course

Why do attackers keep shifting from macros to other delivery methods when email defenses improve?

Attackers adapt quickly when defenders disrupt a common technique. When macro-based delivery becomes less effective, criminals move to other initial access methods such as fake browser updates, drive-by downloads, or conversational phishing. The underlying risk is not the format of the lure, but the ability to persuade a user to trust a malicious path into the environment.

Why delivery methods change when one lure stops working

Attackers are not loyal to macros, files, or any single delivery technique. They are loyal to what still gets code execution, credential capture, or user trust with the least friction. When defenders harden email gateways, disable macros, or train users to spot attachment-based lures, the attacker’s cost goes up and the method becomes less efficient, so they pivot to the next path that still reaches the inbox or browser.

That pivot is usually about preserving the same outcome, initial access, while changing the surface that defenders have learned to block. A technique can fall out of favor even if it is still technically possible, because modern phishing and malware operations are optimized for scale, conversion rate, and evasion rather than consistency.

What the shift looks like in practice

The new delivery method often looks different, but the security objective stays the same. A fake browser update, a drive-by download, a link to a fake login page, or a conversational lure in chat can all replace the macro attachment if they better fit current defenses and user habits. The attacker is adapting the packaging, not abandoning the intrusion goal.

This is why the pattern repeats across threat campaigns. Once one entry path gets noisy, blocked, or expensive to maintain, another is tested. Email filtering may reduce attachment abuse, but it does not remove the broader problem of social engineering, malicious links, or web-based payload staging. The tactic changes because the defender changed the economics of the old tactic.

For defenders, the important distinction is between the delivery channel and the trust mechanism. The delivery channel may be email, web, chat, or collaboration software; the trust mechanism is the user being induced to click, authorize, download, or run something dangerous. If that trust is still exploitable, attackers will keep reusing it in a new wrapper.

Why the underlying problem is user trust, not macros

Macro hardening is useful, but it only removes one implementation of malicious code delivery. It does not solve the broader issue that users can be persuaded to take an unsafe action under believable pretext. That is why conversational phishing, fake alerts, and lookalike sites continue to work even as attachment-based malware delivery becomes harder.

Another reason the shift keeps happening is that attackers can measure defensive pressure quickly. If an organization deploys stronger attachment controls, the operators can watch which lures stop converting and move budget to the ones that still do. In practice, this means delivery methods evolve whenever a common path becomes too detectable, too blocked, or too dependent on outdated user behavior.

The same logic appears in modern attack chains outside email. The initial lure may change, but the later stages often remain familiar: redirect to a malicious page, induce a download, capture credentials, or plant a loader that hands off to a second-stage payload. The delivery technique is only the first adaptation point.

Risk and Threat Considerations

As email defenses improve, attackers often respond by shifting to methods that are less visible to secure email gateways and more reliant on real-time user interaction. That creates a moving target for defenders, because the threat is not just malicious attachments, it is the attacker’s ability to preserve initial access through whatever channel still converts.

Failure mechanism: Defenses suppress one delivery vector, but the attacker preserves the same outcome by moving to a different lure type, such as browser-based deception, direct downloads, or interactive phishing that bypasses attachment-centric controls.

Impact: Organisations can overestimate the value of a single control change if they only measure blocked macros, while the real exposure simply migrates to another channel with similar business impact.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while CIS Controls v8 and OWASP ASVS set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1566 — Phishing Attackers keep changing lures and delivery paths to maintain initial access.
Recommendation — Map current lure patterns to phishing techniques and update detections for the active delivery channel.
CIS Controls v8 CIS-9 — Email and Web Browser Protections The question is about shifting away from email attachments to other email and web delivery paths.
Recommendation — Harden email and browser execution paths together instead of tuning for attachments alone.
OWASP ASVS V12 — Secure Communication The shift to browser and link-based delivery makes transport and user-interaction trust paths material.
Recommendation — Validate that user-facing delivery paths resist link abuse, redirection, and unsafe retrieval.

Practitioner Guidance

What to prioritise: Treat initial-access defense as a channel-spanning problem, not an attachment problem. If your detections and training only focus on Office files, you are already behind the attacker’s substitution cycle.

What to verify: Confirm that your controls cover links, browser downloads, identity prompts, and external-file execution paths, not just macro execution. Watch for whether the user action, not the file type, is the common failure point.

Practitioner takeaway: The goal is to reduce attacker conversion across the full delivery chain, because if the trust path still works, the lure format will keep changing.